Required CVE Record Information
Description
A vulnerability, which was classified as problematic, has been found in Abstrium Pydio Cells 4.2.0. This issue affects some unknown processing of the component Chat. The manipulation leads to basic cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-230213 was assigned to this vulnerability.
CVSS 3 Total
Score | Severity | Version | Vector String |
---|---|---|---|
3.5 | LOW | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
3.5 | LOW | 3.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
4.0 | — | 2.0 | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Credits
- ignatiusmichael (VulDB User) analyst
References 4 Total
- https://vuldb.com/?id.230213 vdb-entrytechnical-description
- https://vuldb.com/?ctiid.230213 signaturepermissions-required
- https://pydio.com/en/community/releases/pydio-cells/pydio-cells-enterprise-421 patch
- https://popalltheshells.medium.com/multiple-cves-affecting-pydio-cells-4-2-0-321e7e4712be exploit
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- https://vuldb.com/?id.230213 vdb-entrytechnical-descriptionx_transferred
- https://vuldb.com/?ctiid.230213 signaturepermissions-requiredx_transferred
- https://pydio.com/en/community/releases/pydio-cells/pydio-cells-enterprise-421 patchx_transferred
- https://popalltheshells.medium.com/multiple-cves-affecting-pydio-cells-4-2-0-321e7e4712be exploitx_transferred